Skip to content
Discussion options

You must be logged in to vote

Hi @benedictweis

The answer to this one depends on which major version of Skupper you are on.

In version 2.0 we are actively working on this - it should be able to handle what you are looking for from 2.1.0+. This may help get you started if that is the case: https://github.com/skupperproject/skupper/tree/main/doc/tls.

Skupper 1.x has an option to supply a skupper-site-ca Secret to a kubernetes site - so you'd have to actually give each site a CA certificate it can use to issue its own certificates. Rotating client and server certificates and CAs wasn't really supported (without destroying and re-initializing a site.)

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@benedictweis
Comment options

Answer selected by benedictweis
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants